Free tools Windows power users keep installed
One-click scans. No signup required.
A business-email-compromise campaign investigated by Sygnia turned compromised employee mailboxes into launchpads for phishing against coworkers and other organizations. The lures posed as shared documents and led recipients through a fake Microsoft sign-in page. Sygnia described the spread as “worm-like,” but did not publish an exact victim count.
How did the scam spread from one company to another?
The campaign relied on trust in ordinary business email. Investigators said attackers compromised an employee account, bypassed Microsoft Office 365 authentication and retained access. They could then use that mailbox—and the organization’s identity—to send plausible messages to colleagues and contacts at other companies.
The phishing emails followed a common template. The title, sender account, company and linked address changed, while the basic shared-document approach stayed much the same. Sygnia researchers said the messages spread “in a worm-like fashion from one targeted company to others and within each targeted company’s employees.” This describes the way the campaign propagated through trusted relationships; it does not mean the emails themselves were a self-replicating computer worm.
What happened when a recipient clicked the shared-document link?
- The email offered a supposed shared document. The link used a file-sharing site whose URL included a previously compromised company’s legitimate name.
- A Cloudflare-protected page appeared. Rather than opening a genuine document, the recipient was routed onward.
- A fraudulent Microsoft authentication page collected credentials. A phishing kit generated the fake sign-in page, making the flow resemble a familiar cloud-service login.
The familiar branding was part of the deception: a Microsoft-looking sign-in page did not establish that the recipient was on a legitimate Microsoft page. The account compromise and continued access allowed attackers to reuse an organization’s email identity to approach more people.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Was this a Microsoft 365 phishing attack?
Microsoft 365 was part of the reported attack chain: CyberScoop reported on June 13, 2023, that attackers bypassed Office 365 authentication, and the lures led to fraudulent Microsoft authentication pages. The available account of the investigation does not specify the technical method used to bypass authentication. It therefore supports describing this as a business-email-compromise campaign involving Microsoft 365 accounts and credential phishing—not claiming a particular Microsoft vulnerability or a specific authentication-bypass technique.
How many companies were affected?
Sygnia described the potential scope as dozens of organizations worldwide, but did not disclose an exact number. The infrastructure findings indicate breadth, not a verified count of victims:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Measure | What investigators reported |
|---|---|
| Potential organizational scope | Dozens of organizations worldwide; exact victim count not disclosed. |
| Domains and subdomains | More than 170 linked to attacker infrastructure. |
| Malicious files | Nearly 100 communicated with that infrastructure; some were associated with the FormBook infostealer malware family. |
These figures describe the investigation, not the number of confirmed compromised companies or the number of people who entered credentials. Domain records showed activity continuing into 2023; the most recent IP address in the investigation dated to January 2023, and domain records were updated June 2, 2023. Those historical indicators do not establish that the same infrastructure remains active now.
What are the warning signs of a fake shared-document email?
A shared-document message can be convincing when it appears to come from a real colleague or business contact. Look at the link and the sequence it triggers, not only the sender name or familiar logo.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- An unexpected document request: You were not expecting the file, or the message gives little context about why it was shared.
- A link that does not match the expected service: Check the full destination domain before signing in. In this campaign, links used a file-sharing site URL containing a previously compromised company’s name.
- A sign-in prompt after clicking a document link: A request to enter work credentials is a reason to verify the page and the share independently, especially if the document has not appeared.
- An unusual message from a familiar account: A known sender’s compromised mailbox can send a plausible-looking lure. Confirm an unexpected share with the sender through a separate, known channel.
- A redirect chain rather than a direct document: The reported flow passed through a Cloudflare-protected page before reaching a fraudulent Microsoft sign-in page.
What should a company do if an employee clicked or entered credentials?
Treat a potentially compromised mailbox as an incident, not just a suspicious email. The account may have been used to target coworkers and external partners, so response speed matters.
- Report it promptly to the organization’s security or IT team. Share the email and link, and say whether credentials were entered. Avoid forwarding the lure to coworkers as a warning.
- Contain the affected account. The response team should secure access and assess whether attackers retain a session or other access. Changing a password alone may not address every form of persistence.
- Investigate the mailbox and identity activity. Check for suspicious forwarding and inbox rules, tokens or sessions, and messages sent from the account. Determine which colleagues or external contacts received the lure.
- Assess exposure beyond the first mailbox. Look for other affected employee accounts, malicious links or files, and relevant activity across the organization’s identity systems.
- Notify recipients and partners through trusted channels. Tell them not to use the link and to report whether they entered credentials or opened a file. This matters because compromised business identities can carry the lure beyond the original company.
- Bring in digital forensics and incident response support if needed. A broad or persistent compromise may require specialist investigation to establish scope, remove access and guide recovery.
Why does this matter financially?
The FBI’s figures provide historical context for business-email compromise, not measurements of this Sygnia investigation. For 2013–2022, the FBI reported more than $50 billion in actual and attempted losses and more than 275,000 BEC attacks. It also reported a 17% increase in identified actual and attempted worldwide losses from December 2021 to December 2022. None of these totals tells us how much this particular campaign stole, or whether any specific target suffered a financial loss.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For organizations, the practical concern is that a mailbox can be both an entry point and a trusted distribution channel. Prompt containment and an investigation of account access, mailbox changes and outgoing messages can help limit further exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




